In memcall_add of memlog.c, there is a possible buffer overflow due to improper input validation. This could lead to loc
PowerShell Elevation of Privilege Vulnerability
PowerShell Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an enabled Autofill service
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, a
A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a l
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability t
This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stac
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to
Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to
PowerShell Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors
Memory corruption while processing API calls to NPU with invalid input.
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result
Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authen
webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack modu
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking
Information disclosure in Core services while processing a Diag command.
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation
In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of ser
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function
An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tool
Froxlor is open source server administration software. Prior to version 2.1.2, it was possible to submit the registratio
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The affected application allows IP configu
.NET Framework Denial of Service Vulnerability
A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an a
NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be us
Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentia
Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentia
Improper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentia
Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation o
Improper input validation in some Intel NUC 8 Compute Element BIOS firmware may allow a privileged user to potentially e
In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path inpu
SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/h
Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to s
Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on W
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of
In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of
The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broa
Transient DOS in Multi-Mode Call Processor while processing UE policy container.
An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the
Vulnerability of input parameter verification in the motor module.Successful exploitation of this vulnerability may affe
Frequently Asked Questions
What is CWE-20?
CWE-20 (Improper Input Validation) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-20?
There are 14,187 CVE records associated with CWE-20 in our database. Of these, 1071 are critical severity, 4031 are high severity, and 3494 are medium severity.
How can I protect against CWE-20 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-20 using AI-powered security agents.
Detect CWE-20 Vulnerabilities
CyberStrike's AI agents automatically detect improper input validation vulnerabilities across your infrastructure.
Get Started